!"#$%&'(%)
*+,-$./01234,556,787498,
:;;< =4,55>,?>@498,
/AB:CD/A4,556587?498,
/AB;<4,5567@-,498,
*+,-EFGA3H 7
I"/$
7& !3J/K:LM<:NOOOOOOOOOOOO&&P
,& K:LM<:N<Q$DOOOOOOOOOOO&&&8
P& K:LM<:N<Q$D%OOOOOOOOOOOO&&&@
?& K:LM<:N<Q$R3L:L3STOOOOOO&7?
8& K:LM<:N<Q$OOOOOOOOOOO&&&&,,
>& K:LM<:N<Q$OOOOOOOOOOO&&&&,6
6& K:LM<:N<Q$OOOOOOOOOOO&&&&&&&&&&&&P,
@& K:LM<:N<Q$OOOOOOOOOOO&&&&&&&&P6
-& K:LM<:N<Q$UDOOOOOOOOOOO&&&&&&&?8
VW$0X'X'JX
7& ./0123$R3L:L3ST4
,& :;;< =$4UD
P& /AB;<$D4D%
?& /AB:CD/A$4
1. Giới thiệu Wireshark
%YZ/Q[3\XGX<]3^X3 _X*3Z` =X`a]M0/)QbXGXcMLLd:]3]X]eM
<X3]facde<A<:]/"g3d:]3]X]eMfEh/<MG3X/iXGX+LMM<L3:<]`jk<,3YX
3Zd:]3]X]eM4`M0/)XGXX3[3\a`IXl<d:]3]XeaN[X]d:]3]X]e3YX3
*+,-EFGA3H ,
XGXa`IXm3Za]`*:(nL+no3Jh/0A:<&*X*3Z` =X3YXJ3:]k
N;XQ` =X+'dp]qXr+'3: _+F3YX 3L:L3&
ML+L3Q3:]*"keJ/& )3Y*Z/X2/3:VXXl<ML+L3aX*3Z3:HX
:V3:<3'`JdX^<3:]`*&/1X…*Z/<]3^Xav3[4H"m4Z/
†eL`w/3MtX^<XGXX/icRf4f%f<AcRDfO
V3<MtM|"mK:LM<:Nd<XNL3MzzL:‡33d$}}ggg&g:LM<:N&]:}ˆX]XGXe<QaA4
X]dodXV3ZJI"/XGX+LMM<L`0` =X|4s3~}3!XGX<]3^Xr
XGX+^X`INGX</Xl<M3<XN<]3^X
2. Wireshark Lab : DHCP
7& '`JdD` =X|h/<UD<A‰
'`JdD` =X|h/<UD
,& ut +I3 "<3<:<+ + C< 3:v 3Y 3_ < Xl< ? * `w/ 3
DMX]L:}zzL:}TLh/LM3}D3:<]`jk<XeL3aML:L:&i*MtX€:<M1
Xj/(aXj`HX&%1Xj3:]H"m` <:<a3:]dŠe<QX*1</
N'‰
*+,-EFGA3H ?
3+L
%:X$5&5&5&5
DLM3$,88&,88&,88&,88
%:X$7-,&7>@&7&7
DLM3$7-,&7>@&7&77,
%:X$5&5&5&5
DLM3$,88&,88&,88&,88
%:X$7-,&7>@&7&7
DLM3$7-,&7>@&7&77,
DML:L: ::XeL3
DMX]L:
zzL:
TLh/LM3
P& ;<X€eN9e<AL:Xl<+GAQFeav‰
;<X€eN9e<AL:ea$55$7L$LX$>>$-6$L?
dụng để phân chia một mạng lớn thành các mạng nhỏ hơn
77& :]H"m4]M3A/Xw/+I3`;<X€3:]DTLh/LM3+LMM<L&F`Œea+v‰
]M3A/Xw/`\;!`;<X€3:]3'`JdD:Lh/LM3
7,& <3HXX^XbXl<eL<ML3+L&F`Œea+eL<ML3+L3:]Q<]e0/‰
L<ML3+Lea3_<+a**eX]Q[33_<+a`;<X€"…&:]e<Q
aA43_<eL<ML3+LeaPaA
7P& ^X‹Xl<D:LeL<ML+LMM<Lea‰DML:L:` <:<3'QG]nGXsA/
Xw/Xl<DXl<XeL3&/AJvMtnA:<[/3j`Jd3~DXl<XeL3Q;+23‰
*+,-EFGA3H >
'`JdD:LeL<ML` =X"…`ZX]Q[3DML:L:+aXeL3`ŒM•Ma
` =X"…X]`;<X€&[/3'`JdD:LeL<MLQ;+233vM</`*`;<X€Mt` =X
"…X]`[N[3F3_<&
7?& a+MG3pQ]]3d†e3L:3:]X|<Mjg:LM<XN&23NŽ*•Ta]X„` =X|]qX
s3:]h/G3:v3:<]"jXGX*
Ty<"":LMMM]e/3]d:]3]X<e{ea<]3^X+a*"…X]JX`G"2/k<`;<
X€a`;<X€&
3. Wireshark Lab : DNS
7& FAMe]]N/d`Ze2A`;<X€Xl<gLQML:L:M<
,& FAMe]]N/d`ZnGX`;D%ML:L:XlXl<+I33: _`FCXr0/•/a]`*
*+,-EFGA3H 6
P& FAMe]]N/d +I33:]XGXD%ML:L:3:]‘/LM3],ea3:/A2`[+<eML:L:Xl<
A<]]+<e
?& .GX`;3'`Jd3:/A2D%a`Gd3:D%&V` =X|h/<<]3^XUD<A
‰
<]3^X$UD
DNS query
D%:LMd]"
*+,-EFGA3H @
8& j`HXXl<3'`Jd3:/A2D%eaQ<]/‰j/(eaQ<]/‰
j/($7-,&7>@&7&75@
AdL$y]M3<"":LMM{
78& <:<N[3h/
7>& '`Jd3:/A2D%|Qb`;<X€a]‰*X*dea`;<X€Xl<D%ML:L:
XmXQI+qX`N'‰
D%h/L:A$7-,&7>@&7&P>
LM
*+,-EFGA3H 75
76& .o33'`Jd3:/A2D%&*3/IXe]Fa]‰*X^<Q23NŽc<MgL:Mf<]N'‰
7@& .o33'`Jd(`Gd&ML:L:Xl<3:e_(`Gdeav‰'`Jd(`GdX„
X^<`;<X€Xl<ML:L:`*`VN]‰
7-& <:<N[3h/+av3/` =X
,5& '`Jd3:/A2D%|`Qb`;<X€a]‰*X*dea`;<X€Xl<D%ML:L:
XmXQI+qX`N'‰[/N'3v`;<X€`*eav‰
Xl<D%h/L:A$7-,&7>@&7&P>
LM
,7& .o33'`Jd3:/A2D%&*3/IXe]Fa]‰*X^<Q23NŽc<MgL:Mfa]N'‰
*+,-EFGA3H 77
,,& .o33'`Jd`Gd3:&*Q<]/e]Fc<MgL:Mf‰3HXXm3Z3~e]F$
,P& <:<N[3h/+av3/` =X
*+,-EFGA3H 7,
4. Wireshark Lab : Ethernet & ARP
& <d3/:<"<<eAƒR3L:L3z:<+LM
7& ;<X€R3L:L3?@9Q3Xl<+GAQFeav‰
*+,-EFGA3H 7P
;<X€R3L:L3?@9Q3Xl<+GAL+ea$55$7Q$zX$P8$"-$?"
,& ;<X€`HX?@Q33:]R3L:L3z:<+Leav‰*d*ea`;<X€R3L:L3Xl<
<<&XM&/+<MM&L"/‰y=W$X0/3:e_eaN'{&[3Q;a]X** ea`;<X€R3L:L3
Xl<*‰
;<X€`HX?@9Q3Xl<R3L:L3z:<+Lea$55$5,$Xz$6L$7P$"L
0AN'd`;<X€R3L:L3Xl<<<&XM&/+<MM&L"/+aea`;<X€Xl<:]/3L:“A<3L4v*
*68QA3L3H3~Qx3`w/Xl<R3L:L3z:<+L`Zn/23J+Œ%cf3:]cf
*+,-EFGA3H 7>
75& G3:;Ln<Xl<3: _T3:]R3L:L3z:<+L&
a?QA3LX/1X…Xl<R3L:L3z:<+LX*G3:;ea$]"]<]"]<
& L"":LMMTLM]e/3]:]3]X]e
77& u[3:<XGXI"/X<XLTXl<+GA3HXl<QF&–”<Xl<+iXI3G3:;eav‰
<XLTQ<](+X*`;<X€rXI33L:L3"":LMM4`;<X€rXI3AMX<e"":LMMa
XI3AdLeaX€NZ/<]3^X
7,& G3:;Ln<Xl<`;<X€/(a`HX3:]R3L:L3z:<+L43^X^<3'`JdT‰
*+,-EFGA3H 76
G3:;Ln<Xl<`;<X€/(ea$55$"5$8-$<-$P"$>@
G3:;Ln<Xl<`;<X€`HXea$zz$zz$zz$zz$zz$zzv`0Aea`;<X€h/QG&
7P& <`;<X€Ln<Xl<3: _NZ/R3L:L3z:<+L,9QA3L&GXQ3G3:;7”<eav
3:]3: _†e<&
G3:;Ln<Xl<3: _3AdLea$5n5@5>eaNZ/T
7?& n/1XGX`qX3T3~z3d$}}z3d&:zX9L"3]:&]:}9]3LM}M3"}M3"P6&3n3&73]e/s
X3[3X*3Z`CX` =XXl<TX„r
33d$}}ggg&L:&<Q"&<X&/N}/ML:M}]::A}X]/:ML}L39d<LM}<:d&3+e
<{ *Q<]/QA3L3H3~`Z+Qx3`w/Xl<R3L:L3z:<+L+a3: _]dX]"LTQx3
`w/
Q{ G3:;Xl<3: _]dX]"L3:]dwT9d<Ae]<"Xl<R3L:L3z:<+L+ar`*7A/
Xw/T` =X3F]:<‰
X{ '`JdTX^<<AN'`;<X€Xl< _|yML"L:{‰
"{ )a]3:]A/Xw/T+ach/LM3]fn/23JE;<X€R3L:L3Xl<+GA3H
+a`;<X€3 )^`<` =X3:/A2&
:e_$
*+,-EFGA3H 7@
<{ : _]dX]"LQx3`w/M</,5QA3L3H3~`0/R3L:L3z:<+L&
Q{ G3:;Xl<3: _]dX]"L3:]dwT9d<Ae]<"Xl<R3L:L3z:<+L+ar
NGX&FM<]r`0AN'X*Td(y|d(X]A/Xw/T3:]d<XNL3>{
3:]d<XNL33:<XLaA‰
*+,-EFGA3H ,5
uvXGXA/Xw/T` =Xh/QG d(T3v|3:YX3[d3!+GA3HX*`;<
X€R3L:L3`Œ|A/Xw/4"]sA+GA3HXV3<N'dea+GA3H`Œ|A/Xw/
TN's` =Xd(T+aX€s` =XA/Xw/Th/QG&
VW`;<X€+GA3HXV3<ea$55$"5$8-$<-$P"$>@3:]N`*`;<X€Xl<+GA3Hs
ea55$@5$<"$6P$@"$XL
5. Wireshark Lab : HTTP
7& :v"/AJ3Xl<QFXFAdQ7&5<A7&7‰QXl<` =XML:L:
XFA‰
3:v"/AJ3aML:L:`\/XFAdQ7&7
*+,-EFGA3H ,7
,& 'k+a3:v"/AJ3gLQXl<QFX€:<*X*3ZX2dsML:L:
'k3:v"/AJ3X2dsea3[<&
P& ;<X€<"":LMMXl<+GAQFa<<&XM&/+<MM&L"/ML:L:‰
;<X€+GA/(ea$7-,&7>@&7&75,
;<X€Xl<ML:L:ea$7,@&77-&,?8&7,
?& Œ3:F3G` =X3:\3~ML:L:X]3:v"/AJ3Xl<QF&
Œ3:F3G` =X3:\3~ML:L:X]3:v"/AJ3ea$,55
ŒaAQG]A/Xw/3aX'a`13 =` =XA/Xw/rM</3:]3'`JdaA&
8& _`Z+†eL+aQF`<s` =XX€M|<ewX/1rML:L:‰
_`Z+†eL` =XX€M|<ewX/1rML:L:ea$
>& *Q<]/QA3L3:]I"/` =X3:\X]3:v"/AJ3Xl<QF‰
%1QA3LI"/3:\X]3:v"/AJ3ea6P
*+,-EFGA3H ,,
6& bXGXnL+no3"keJ/3'3:]X|<MjI"/d<XNL34QF32A<AN'Q23NŽ
XGXL<"L:Q3:]"keJ/43^N'` =XZ3;3:]X|<Mjd<XNL39eM3‰[/
X*4C373:]M1`*&
'd323XXGXL<"L:`\/Z3;3:]X|<Mjd<XNL39eM3&
X€3L:L3a]` =XXGXA/X0/R|3!‰
*P3'`JdA/Xw/R` =X|Qr3:v"/AJ34XGX`;<X€` =XA/Xw/
R|3!ea$
—7,@&77-&,?8&7,
—7>8&7-P&7,P&,7@
—7P?&,?7&>&@,
76& FX*3Z*X*<AN'3:v"/AJ3Xl<QF"]ge]<",3/w3Y<AXV
` =X"]ge]<"3~,3:<gLQM]M]‰3HX
˜`0A,` =X"]ge]<"3/w3Y&<X*3Z32Ah/<3_<"]ge]<"z:<+L`*\
7@& pd(vXl<ML:L:ydwaX]"L3:F3G{3!3'`JdRQ<`w/
3~3:v"/AJ3Xl<QF‰
Œd(ea$?57
<:ML$/3L:ƒ<3]TLh/:L"
*+,-EFGA3H ,8